Hi all,
Between nightmarish licensing scenarios, potentially insecure features that deploy "on" by default, documentation that's outdated 5 minutes after published, a push to over-share everything, and critical security features (like DLP) where functionality is inconveniently split across licensing tiers, how does Microsoft expect a business to adequately secure their cloud-based assets?
But then again, maybe I shouldn't be surprised given that this was the company that produced generation after generation of OS that automatically established the new user's account as a full local admin...
Can anyone provide tips, other helpful threads, or recommend resources dedicated to helping infosec teams gain mastery in securing the Microsoft Office 365 environment? (Ideally something a little more focused than a generic cloud security bootcamp intended for CCSP applicants...) Am I stuck having to kowtow to the Evil Empire for this? I'm working for an educational organization that took the well-trodden path of so many others before them (deploy everything now, work on buttoning it up later) and so our security team is now digging into Azure, O365/Exchange, Power BI, Graph, and all these other woefully complex and interwoven environments. Our license spreadsheet is a 32 line item mishmash of As and Es, Plan variants, Trials, Frees, and Pros. Youtube videos aren't much use to me because I'll spend 30 minutes watching a walk through only to discover that those features aren't available to us. Microsoft Docs and countless online blogs are only slightly more useful (in that they're more likely to indicate what licensing you need to have in place to perform the functions) -- but then they preface the article with a statement like "Please note, this is applicable as of April 2018, and may change once X feature is deployed." Ugh.
It would seem to me that more often than not all an IT group is accomplishing by moving more infrastructure to the cloud is to exchange the fickleness of on-prem iron for the fickleness of Microsoft engineers... Thankfully we do have some features turned off since deploy, but it's growing more difficult for us to convince an org riddled with folks antsy to launch pet projects that something needs to REMAIN off, than it is them convincing the business that we need to turn it on.
Your help is appreciated. Thanks!
submitted by [comments]
SOCIAL SHARE CARD GENERATOR